Three MSPs can sell three wildly different services and stick the same "managed IT" label on the front. I have sat with clients who thought they had 24/7 monitoring and instead got a bloke who appears only when the server dies. The labels matter. Get them wrong and you overpay for hand-holding you never needed, or you stand there bare when a ransomware note lands on a Tuesday morning. Here is how the three models work, and the questions to ask before you sign.
What does break-fix IT support actually mean
Break-fix means exactly what it says. Something breaks, you call, they fix it, you get billed for the hours. No monthly retainer. No proactive monitoring. No patching schedule unless you buy it separately. It is the oldest model in IT support and it still has a place.
The issue is not break-fix, it is providers dressing it up as something broader. If the contract has no monitoring clause and no defined response time, you are on break-fix whatever the sales deck claims. That suits a five-person shop with low-risk data and a director who can live with losing a day if the printer server dies. It is a poor fit for anyone touching customer payment data or running anything customer-facing.
What is fully managed IT and what should be included
Fully managed means the provider owns the outcome, not just the visit. Expect proactive monitoring, patch management, endpoint protection, backup oversight, a help desk with agreed response times, and someone accountable when alarms go quiet at 2am. You pay a flat monthly fee, so the incentive flips. Fewer fires, fewer billable hours, better outcomes.
This is the label most often abused. I have seen "fully managed" packages that are break-fix in a subscription wrapper with a monitoring dashboard nobody reads. Ask which tasks are proactive and which are reactive, in the contract, line by line. If the answer is fuzzy, you have your answer.
How does co-managed IT work when you already have in-house staff
Co-managed IT fits businesses with an internal IT person or small team who cannot cover everything. Perhaps you have someone brilliant at desktop support but little cybersecurity depth, or someone who knows your industry software but has never written a disaster recovery plan. Co-managed fills the gaps instead of replacing the whole function.
Done well, the MSP takes ownership of patching, backup verification, security monitoring and compliance documentation, while your in-house person keeps the day-to-day work they are strong at. Done badly, it is two teams pointing at each other when something breaks and nobody owning the outage. The contract must spell out who is responsible for what, down to the ticket level.
When does break-fix still make financial sense
Break-fix suits businesses with genuinely low IT complexity: a few laptops, cloud software managed by the vendor, and no regulatory duty to prove security controls. If your worst downtime scenario is "we lose an afternoon" rather than "we lose customer trust and face a data protection complaint", a fully managed contract is often money spent on peace of mind you do not need yet.
The catch is that firms grow into complexity faster than they update the IT contract. A company on break-fix for three years usually has more devices, more cloud accounts and more customer data than day one, with none of the monitoring to match. Review the fit every year. Do not set and forget.
When do you actually need fully managed IT
Fully managed earns its keep once downtime has a real price tag, or once you are handling data that puts you in scope for GDPR, PCI DSS or an insurer’s security questionnaire. It is also the right call once nobody internally can tell good IT hygiene from bad. If nobody in the building would notice a server silently failing to back up for two months, you need eyes on it at all times, not a callout number.
This is where the specific service types on our MSP directory matter, because "managed IT" as a single label hides a lot. A proper managed contract should break out clearly into managed IT support, cybersecurity monitoring, cloud management, backup and disaster recovery, and compliance support. If a provider bundles the lot into one vague line with one price, ask them to unbundle it so you can see what you are buying.
What questions should you ask before choosing a model
Get the response time SLA in writing. Confirm whether monitoring is truly 24/7 or business hours with alerts checked the next morning. Pin down who owns backup testing and how often results are verified, not just scheduled. Ask what happens at 3am on a bank holiday if a server goes down, and get a name or an escalation path, not "we’ll sort it".
For co-managed setups, ask for a RACI-style breakdown of who does what. Lines like "we work alongside your team" mean nothing until someone writes down who patches the firewall and who is accountable if it does not get patched.
How do you compare quotes that use different labels for the same thing
Ignore the marketing and compare the deliverables: response time, monitoring hours, patching cadence, backup testing frequency and the exclusions. Two quotes priced miles apart for "fully managed" usually differ because one includes 24/7 security monitoring and one does not, not because one provider is simply better value.
If you want a faster way to map your risk profile before collecting quotes, our MSP Readiness Index walks through the same questions in a couple of minutes and points you towards break-fix, co-managed or fully managed based on your actual setup rather than what a sales call nudges you into.
What should MSPs do to label their services honestly
If you run an MSP and you are wondering whether your own listing is clear, it is probably not as clear as you think. Buyers get burned by vague labels all the time, and it costs providers referrals when a client feels misled after signing. Be explicit about what is break-fix, what is co-managed and what is genuinely fully managed, with the specific service types spelled out. That builds more trust than another line about "world-class support".
You can claim your listing on HostList and set out exactly which service types you offer against the categories buyers search for: managed IT, cybersecurity, cloud, backup, co-managed and compliance. Honest labelling gets you fewer time-wasting enquiries and more clients who already know what they are buying.
Follow HostList for new rankings, original research, and changes across the hosting industry.



